Top Tweets for #SideCopy
Pakistan-linked SideCopy targets Afghanistan's Finance Ministry with Xeno RAT in Operation XENOFISCAL. Link: https://t.co/1ZIPBG1fSm #SideCopy #XenoRAT #XENOFISCAL #Afghanistan #Finance #Ministry #Phishing #Malware #Spyware #RAT #Cybersecurity #Infosec #ThreatIntel #APT36 #Pakistan #Espionage #Attack #Campaign #Targeting #Breach

A deep look at the SideCopy XenoRAT malware attack targeting the Afghan Ministry of Finance. Learn how Operation XENOFISCAL bypasses defenses.
#SideCopy #XenoRAT #CyberSecurity #OperationXENOFISCAL #ThreatIntel
https://t.co/AR3xOpcyWd

#ThreatProtection Operation #XENOFISCAL attributed to Pakistan-linked #SideCopy, which uses in-memory loaders and encrypted C2 channels to deploy XenoRAT and maintain covert access within government environments, read more: https://t.co/gNI6rgfDZx
SideCopy APT targets Afghanistan's Finance Ministry with XenoRAT malware in Operation XENOFISCAL. Learn about their sophisticated attack methods and how to protect your organization. Link: https://t.co/SuDbJkSSzT #SideCopy #XenoRAT #Afghanistan #Finance #Ministry #Malware #Cyberattack #APT #Espionage #Phishing #RAT #Infosec #ThreatIntel #Breach #Defense #Security #OperationXENOFISCAL #Surveillance #Intrusion #Targeting

Seqrite Labs tied Operation XENOFISCAL to SideCopy, using a Pashto-named LNK and multi-stage loader to deploy persistent XenoRAT against Afghanistan's Ministry of Finance and provincial Mustoufiats. #Afghanistan #SideCopy #XenoRAT
https://t.co/uJJdhjA66E
#Fofa Query for #DeskRAT Infra of #SideCopy #APT
Query: header="HTTP/1.1 503 Service Unavailable" && header="Content-Length: 238" && asn="200019"
Link: https://t.co/YFa9NbiLip
Infra (Including enrichment from VT): As observed earlier, all IP addresses belongs to the same ASN "Alexhost SRL"
IP Addresses:
---------------------
85.137.249[.]224:8080
85.137.249[.]243:8080
193.233.244[.]243:8080
45.90.97[.]211:8080
87.120.244[.]90:8080
87.120.244[.]206:8080
45.155.54[.]113:8080
46.253.4[.]33:8080
45.155.54[.]123:8080
45.155.54[.]253:8080
45.155.54[.]22:8080
Domains:
---------------------
chuchuchacha[.]shop
chuchuchacha[.]xyz
chuchuchachawin[.]bond
chuchuchachawin[.]sbs
echs[.]online
forwindowstesting[.]site
forwindowstesting[.]space
ftp.czwaluk[.]de
makiinindia[.]online
makiinindia[.]xyz
vayusena[.]store
vayusena[.]online
vdsd.whypay[.]info
#APT36 #Malware #ioc
![Cyberteam008's tweet photo. #Fofa Query for #DeskRAT Infra of #SideCopy #APT
Query: header="HTTP/1.1 503 Service Unavailable" && header="Content-Length: 238" && asn="200019"
Link: https://t.co/YFa9NbiLip
Infra (Including enrichment from VT): As observed earlier, all IP addresses belongs to the same ASN "Alexhost SRL"
IP Addresses:
---------------------
85.137.249[.]224:8080
85.137.249[.]243:8080
193.233.244[.]243:8080
45.90.97[.]211:8080
87.120.244[.]90:8080
87.120.244[.]206:8080
45.155.54[.]113:8080
46.253.4[.]33:8080
45.155.54[.]123:8080
45.155.54[.]253:8080
45.155.54[.]22:8080
Domains:
---------------------
chuchuchacha[.]shop
chuchuchacha[.]xyz
chuchuchachawin[.]bond
chuchuchachawin[.]sbs
echs[.]online
forwindowstesting[.]site
forwindowstesting[.]space
ftp.czwaluk[.]de
makiinindia[.]online
makiinindia[.]xyz
vayusena[.]store
vayusena[.]online
vdsd.whypay[.]info
#APT36 #Malware #ioc](https://pbs.twimg.com/media/HHm1Z7baUAADZ8c.jpg)
In January 2026, NSFOCUS Security Lab discovered a total of 26 #APT attack activities. The most active APT groups in January were #Lazarus from South Asia, #SideCopy and #TransparentTribe from South Asia, and #Kimsuky from East Asia. https://t.co/yBiVWGZl5f
Threat Alert:
#SideCopy — New Samples Beaconing to Known C2
Hashes:
e8e7a86c9e3509bf503fd496489095eb4806ccd615c12219c7a0fad73283eeca
1e36f9bb209002db499b2d4df91d412462a7f1b6d04db0e8a4f95dba19e3ce2a
C2: dns[.]wmiprovider[.]com
ThreatBook Intelligence: https://t.co/iF95ZypJP1
![ThreatBookLabs's tweet photo. Threat Alert:
#SideCopy — New Samples Beaconing to Known C2
Hashes:
e8e7a86c9e3509bf503fd496489095eb4806ccd615c12219c7a0fad73283eeca
1e36f9bb209002db499b2d4df91d412462a7f1b6d04db0e8a4f95dba19e3ce2a
C2: dns[.]wmiprovider[.]com
ThreatBook Intelligence: https://t.co/iF95ZypJP1 https://t.co/0Hxx0nvw3l](https://pbs.twimg.com/media/HDBJhnqaMAcoCh6.png)
#APT36 #SideCopy #APT #Phishing
documentcentre[.]in
docsportal[.]in #opendir
ISO/ZIP > LNK > HTA
#C2 #GetaRAT
dns.sysdllt[.]xyz
45.61.157[.22:5863
144.172.89[.29:5941
@500mk500
DoCDWork()
Public\User\startT.hta, appT.bat, runT.bat
Public\Config\Config.hta, CerT.bat, SigT.bat
![PrakkiSathwik's tweet photo. #APT36 #SideCopy #APT #Phishing
documentcentre[.]in
docsportal[.]in #opendir
ISO/ZIP > LNK > HTA
#C2 #GetaRAT
dns.sysdllt[.]xyz
45.61.157[.22:5863
144.172.89[.29:5941
@500mk500
DoCDWork()
Public\User\startT.hta, appT.bat, runT.bat
Public\Config\Config.hta, CerT.bat, SigT.bat https://t.co/Dj7786wO18](https://pbs.twimg.com/media/HCp7U8iakAElH90.png)
#APT36 (ISO-LNK-BAT) triggers HTA-based #ReverseRAT & #GetaRAT, instead of CrimsonRAT [seen early Dec-2025]
commskl.iso
7edf05d02d84b160b39e4e778a226959
commskl.docx.lnk
7f735f1605a54a18072f299a14507a5d
#C2 AS14956
172.86.122[.]203:5863
dns.sysdllfile[.]site
@500mk500
![PrakkiSathwik's tweet photo. #APT36 (ISO-LNK-BAT) triggers HTA-based #ReverseRAT & #GetaRAT, instead of CrimsonRAT [seen early Dec-2025]
commskl.iso
7edf05d02d84b160b39e4e778a226959
commskl.docx.lnk
7f735f1605a54a18072f299a14507a5d
#C2 AS14956
172.86.122[.]203:5863
dns.sysdllfile[.]site
@500mk500 https://t.co/93fpuO6IWC](https://pbs.twimg.com/media/HBsWwh_bgAUHf0W.png)
APT36 and SideCopy Launch Cross-Platform RAT Campaigns Against Indian Entities https://t.co/Oxg4YL9Mri
#APT36 #SideCopy #RAT #campaign #remoteaccesstrojan #cyberattack
#APT36 and #SideCopy Launch Cross-Platform #RAT Campaigns Against #Indian_Entities
https://t.co/LpsPBKY4Mq


APT36(Transparent Tribe)とSideCopyがWindows+Androidを狙うクロスプラットフォーム攻撃を展開。スピアフィッシングでバックドアとAPK配布、軍・政府関係者が標的。モバイルEDR強化が重要。 #APT36 #SideCopy #CyberEspionage https://t.co/c0HjVJrn3z
APT36 and SideCopy Launch Cross-Platform RAT Campaigns Against Indian Entities - https://t.co/JHxFiPWq4p #campaigns #sidecopy #against
iT4iNT SERVER APT36 and SideCopy Launch Cross-Platform RAT Campaigns Against Indian Entities https://t.co/El9N5p1zsW VDS VPS Cloud #CyberSecurity #Malware #RAT #APT36 #SideCopy
APT36 & SideCopy hit Indian orgs with cross-platform RATs (Geta, Ares, DeskRAT) for data theft & persistence. 🚨 Info here: https://t.co/ZaWIXr31HG #CyberAttack #APT36 #SideCopy #RAT #India
Most Popular Users

Elon Musk 
@elonmusk
240.1M followers

Barack Obama 
@barackobama
119.3M followers

Donald J. Trump 
@realdonaldtrump
111.6M followers

Cristiano Ronaldo 
@cristiano
108.7M followers

Narendra Modi 
@narendramodi
106.9M followers

Rihanna 
@rihanna
97.2M followers

NASA 
@nasa
92.1M followers

Justin Bieber 
@justinbieber
90.5M followers

KATY PERRY 
@katyperry
86.7M followers

Taylor Swift 
@taylorswift13
80.5M followers

Lady Gaga 
@ladygaga
72.1M followers

Kim Kardashian 
@kimkardashian
69.3M followers

YouTube 
@youtube
68.6M followers

Virat Kohli 
@imvkohli
68.4M followers

Bill Gates 
@billgates
63.4M followers

The Ellen Show
@theellenshow
62.5M followers

CNN 
@cnn
61.9M followers

Neymar Jr 
@neymarjr
60.9M followers

X 
@x
60.9M followers

CNN Breaking News 
@cnnbrk
59.9M followers




![NetSecIO's tweet photo. APT group SideCopy targets Afghanistan's Finance Ministry in 'Operation XENOFISCAL.' The campaign uses Pashto-language spear-phishing lures to deploy the XenoRAT trojan for espionage. 🇵🇰-aligned group continues focus on South Asia. #APT #SideCopy #...
🌐 cyber[.]netsecops[.]io https://t.co/JC0UG9oHj8](https://pbs.twimg.com/media/HJ0fQQyXoAAYmb-.jpg)






![ThreatBookLabs's tweet photo. Threat Alert:
#SideCopy — New Samples Beaconing to Known C2
Hashes:
e8e7a86c9e3509bf503fd496489095eb4806ccd615c12219c7a0fad73283eeca
1e36f9bb209002db499b2d4df91d412462a7f1b6d04db0e8a4f95dba19e3ce2a
C2: dns[.]wmiprovider[.]com
ThreatBook Intelligence: https://t.co/iF95ZypJP1 https://t.co/0Hxx0nvw3l](https://pbs.twimg.com/media/HDBJhYhacAAvOhA.jpg)

![PrakkiSathwik's tweet photo. #APT36 #SideCopy [1/2]
Advisosry Fake Websites Seeking Beneficiary Data1 (1).zip {x2} -> desktop / #LNK
Advisosry Fake Websites.desktop
e10923fbfebbac23650756e77045533b
ashraagrotech[.]com
#C2
2.56.10.101:6357 - flow.hta #GetaRAT
2.56.10.121:52145 - vcache #AresRAT
@500mk500 https://t.co/C4HsexijZH](https://pbs.twimg.com/media/HC0tR5JaEAAf0yk.png)

![PrakkiSathwik's tweet photo. #APT36 #SideCopy #APT #Phishing
documentcentre[.]in
docsportal[.]in #opendir
ISO/ZIP > LNK > HTA
#C2 #GetaRAT
dns.sysdllt[.]xyz
45.61.157[.22:5863
144.172.89[.29:5941
@500mk500
DoCDWork()
Public\User\startT.hta, appT.bat, runT.bat
Public\Config\Config.hta, CerT.bat, SigT.bat https://t.co/Dj7786wO18](https://pbs.twimg.com/media/HCp7UFCasAAQvAD.jpg)
![PrakkiSathwik's tweet photo. #APT36 #SideCopy #APT #Phishing
documentcentre[.]in
docsportal[.]in #opendir
ISO/ZIP > LNK > HTA
#C2 #GetaRAT
dns.sysdllt[.]xyz
45.61.157[.22:5863
144.172.89[.29:5941
@500mk500
DoCDWork()
Public\User\startT.hta, appT.bat, runT.bat
Public\Config\Config.hta, CerT.bat, SigT.bat https://t.co/Dj7786wO18](https://pbs.twimg.com/media/HCp7TB5bQAAuhTM.png)
![PrakkiSathwik's tweet photo. #APT36 #SideCopy #APT #Phishing
documentcentre[.]in
docsportal[.]in #opendir
ISO/ZIP > LNK > HTA
#C2 #GetaRAT
dns.sysdllt[.]xyz
45.61.157[.22:5863
144.172.89[.29:5941
@500mk500
DoCDWork()
Public\User\startT.hta, appT.bat, runT.bat
Public\Config\Config.hta, CerT.bat, SigT.bat https://t.co/Dj7786wO18](https://pbs.twimg.com/media/HCp7STobwAA0MaV.png)
![PrakkiSathwik's tweet photo. #APT36 (ISO-LNK-BAT) triggers HTA-based #ReverseRAT & #GetaRAT, instead of CrimsonRAT [seen early Dec-2025]
commskl.iso
7edf05d02d84b160b39e4e778a226959
commskl.docx.lnk
7f735f1605a54a18072f299a14507a5d
#C2 AS14956
172.86.122[.]203:5863
dns.sysdllfile[.]site
@500mk500 https://t.co/93fpuO6IWC](https://pbs.twimg.com/media/HBsWp-FbgAAbuRh.png)
![PrakkiSathwik's tweet photo. #APT36 (ISO-LNK-BAT) triggers HTA-based #ReverseRAT & #GetaRAT, instead of CrimsonRAT [seen early Dec-2025]
commskl.iso
7edf05d02d84b160b39e4e778a226959
commskl.docx.lnk
7f735f1605a54a18072f299a14507a5d
#C2 AS14956
172.86.122[.]203:5863
dns.sysdllfile[.]site
@500mk500 https://t.co/93fpuO6IWC](https://pbs.twimg.com/media/HBsWo9CbgAUJQse.jpg)
![PrakkiSathwik's tweet photo. #APT36 (ISO-LNK-BAT) triggers HTA-based #ReverseRAT & #GetaRAT, instead of CrimsonRAT [seen early Dec-2025]
commskl.iso
7edf05d02d84b160b39e4e778a226959
commskl.docx.lnk
7f735f1605a54a18072f299a14507a5d
#C2 AS14956
172.86.122[.]203:5863
dns.sysdllfile[.]site
@500mk500 https://t.co/93fpuO6IWC](https://pbs.twimg.com/media/HBsWnyXaAAAojjT.jpg)






